About This Architecture
Unicaja's hub-and-spoke zero-trust network architecture spans Azure subscriptions with Palo Alto NGFW inspection at the hub, connecting on-premises infrastructure via ExpressRoute and securing public ingress through Akamai WAF. Traffic flows through mandatory inspection points enforcing least-privilege access across DMZ, application, ARO Kubernetes, and shared services spokes. The design isolates workloads—Azure Functions, App Services, and a fully private OpenShift cluster—while centralizing DNS resolution and CI/CD pipelines in dedicated spokes. This architecture demonstrates enterprise-grade network segmentation, compliance-ready logging via Azure Monitor and Log Analytics, and defense-in-depth with NSGs, UDRs, and DDoS protection. Fork and customize this diagram on Diagrams.so to adapt the hub-and-spoke topology, adjust CIDR ranges, or document your own zero-trust perimeter.